You must quantify risk using SLE, ARO, and ALE, then compare residual risk against the stated appetite to recommend treatment. The single most important thing: risk decisions and acceptance belong to the business owner, while security advises, monitors, and reports.
Start practicing
Information Security Risk Management — choose a session length
Free · No account required
Domain overview
CISM Domain 2 covers risk identification, analysis, evaluation, treatment, and monitoring aligned to organizational risk appetite and tolerance. Questions test quantitative methods like SLE, ARO, and ALE, qualitative heat maps, control selection, residual risk calculation, and communicating risk to senior leadership. Expect scenario-based judgment calls on ownership, acceptance, and escalation rather than pure definitions.
Exam objectives
Calculating SLE, ARO, and ALE to justify or reject a safeguard's cost
Distinguishing inherent risk, residual risk, risk appetite, and risk tolerance
Assigning risk ownership to business process owners, not information security
Selecting risk treatment: mitigate, transfer, avoid, or accept with approval
Confusing risk appetite (desired level) with risk tolerance (acceptable deviation) and applying them interchangeably in scenario answers
Treating residual risk as zero after controls are implemented instead of recalculating likelihood and impact
Assuming information security owns business risk; accountability stays with the business process or asset owner
Click any question to see the full explanation and answer options, or start a focused practice session above.
A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?
2An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?
3During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?
4In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?
5A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?
6Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)
7Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)
8You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?
9An organization has implemented a new web application that processes sensitive customer data. The risk assessment identified a high likelihood of SQL injection attacks due to insufficient input validation. Which of the following is the BEST risk treatment strategy?
10An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?
11A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?
12Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?
13Which of the following are key components of an Information Security Risk Management program? (Select TWO.)
14Which of the following is the PRIMARY purpose of an information security risk assessment?
15An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?
16During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?
17A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)
18Order the steps for implementing a security awareness training program.
19Order the steps for implementing a data classification policy in an organization.
20Match each risk management term to its definition.
21Match each business continuity term to its definition.
22An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?
23A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?
24After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?
25A risk manager is presenting risk treatment options to senior management. Which of the following is the BEST approach to communicate risk in a way that supports informed decision-making?
26A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?
27During a risk assessment, the risk team identifies that a key vendor has access to sensitive data. The vendor's security posture is unclear. Which of the following is the BEST course of action?
28Which of the following best describes residual risk?
29A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?
30An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?
31Which TWO of the following are key components of an information security risk assessment? (Choose two.)
32Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)
33Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)
34A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?
35During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?
36A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?
37An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?
38A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?
39An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
40A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?
41During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?
42An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?
43Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)
44Which TWO of the following are examples of risk mitigation controls? (Choose two.)
45Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?
46An organization calculates that the single loss expectancy (SLE) for a server failure is $10,000, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
47A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?
48Which of the following best describes the difference between risk appetite and risk tolerance?
49After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?
50A security manager is preparing a risk report for the board of directors. Which of the following should be included to best support strategic risk-based decisions?
51Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
52Which TWO of the following are common approaches to information security risk assessment?
53Which THREE of the following are essential components of an information security risk management framework?
54A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?
55After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?
56A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?
57A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?
58A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?
59An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?
60Which of the following is the primary purpose of communicating risk assessment results to senior management?
61A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?
62Which TWO of the following are risk treatment strategies as defined in ISO 27005?
63Which THREE of the following are typical steps in a qualitative risk assessment?
64A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?
65A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?
66A small accounting firm with 50 employees recently suffered a ransomware attack that encrypted all client data on its file server. The firm had no backup strategy, and the attackers demanded a ransom for decryption. The firm paid the ransom, but many clients left due to loss of trust. The firm’s owner has now hired you as a part-time risk manager. Your first task is to develop a risk management program. What is the most appropriate initial step?
67A regional hospital is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). During an internal audit, it was discovered that patient electronic health records (EHRs) are transmitted over the internet without encryption. The risk manager has been asked to recommend a risk treatment. Which action should be prioritized to address this finding?
68A large retail chain with hundreds of stores uses point-of-sale (POS) systems that run an outdated operating system. The annual risk assessment identified this as a high-risk issue because the OS is no longer patched and has known vulnerabilities. The business unit manager opposes replacing all POS systems immediately due to cost and potential disruption to operations. As the risk manager, you need to recommend a risk response that balances risk reduction with business continuity. Which strategy is most appropriate?
69A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?
70A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?
71An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?
72A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?
73An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?
74A global insurer completes an annual enterprise risk assessment and reports its top information security risk as a residual risk score of 16 (5x3 on a 5x5 matrix) after applying a data loss prevention solution and security awareness training. The board has stated that any residual risk above 12 must be escalated for a formal risk treatment decision. The CISO is asked to present options at the next risk committee meeting. Which of the following is the MOST appropriate action for the CISO to take FIRST?
75A healthcare insurer has completed an annual risk assessment. The CISO must present the results to the board and recommend a treatment strategy for a risk involving a legacy claims-processing application. The board has stated that it will not accept any risk that could result in a regulatory fine exceeding $1 million. Which of the following is the MOST appropriate action for the CISO to take FIRST?
76A global manufacturing firm is expanding into a new region where data residency laws differ significantly from its home country. The CISO must present a risk treatment plan to the board. Which of the following is the MOST appropriate FIRST step in aligning risk treatment with the organization's risk appetite?
77A global insurance provider has completed a risk assessment for a new policyholder web portal. The risk treatment plan includes purchasing cyber insurance to transfer a portion of the financial impact. Which of the following is the PRIMARY consideration when evaluating this treatment option?
78A global insurance provider has just completed a quantitative risk assessment for a new claims-processing application. The assessment used the Annualized Loss Expectancy (ALE) formula and produced an ALE of $850,000 for the risk of a data breach. The vendor's proposed control has an Annualized Cost of the Safeguard (ACS) of $300,000 and a projected risk reduction of 60%. The CISO asks the information security manager to determine the cost-benefit of implementing this control. What is the net benefit (or loss) of the control?
79An information security manager is reviewing a risk register that contains a risk with a risk score of 20 (likelihood 5, impact 4). The risk owner proposes to accept the risk because the cost of mitigation exceeds the potential loss. Which of the following should the security manager do NEXT?
80An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?
81A healthcare organization is conducting a risk assessment for a new telehealth platform that will process protected health information. The assessment team proposes using a qualitative approach because of tight deadlines. Which of the following is the MOST significant limitation of relying solely on qualitative risk assessment for this initiative?
82A healthcare organization is evaluating a new telehealth platform that will process protected health information. The security manager has completed a risk assessment and identified several risks. The CISO asks which of the following is the MOST important factor when determining whether to accept, mitigate, transfer, or avoid a risk?
83A healthcare organization is conducting a risk assessment for its electronic health record (EHR) system. The security manager is identifying threats and vulnerabilities. Which TWO of the following are considered vulnerabilities rather than threats? (Choose two.)
84A global manufacturing firm is establishing a formal risk management program. The CISO has been asked to ensure that risk assessment outputs are consistently comparable across business units and over time. Which TWO of the following practices BEST support this objective? (Choose two.)
85A retail company's risk register lists a vulnerability in its point-of-sale system that could expose customer payment card data. The Chief Information Security Officer (CISO) wants to ensure the risk is managed appropriately. Which of the following should be the FIRST step in the risk treatment process?
86A retail company is building an information security risk register to support its risk management program. The risk manager wants to ensure the register captures the information needed to track and report risks to senior management. Which TWO of the following are essential elements that should be included for each identified risk? (Choose two.)
87A retail company has a risk register that includes a risk related to point-of-sale (POS) malware. The risk owner has decided to implement an endpoint detection and response (EDR) solution to reduce the risk. Which risk treatment strategy is being applied?
88An information security manager is updating the organization's risk register after a significant change in the threat landscape. The manager needs to ensure the register remains a useful tool for decision-making. Which TWO of the following activities are MOST important for maintaining the risk register's effectiveness? (Choose two.)
89A retail company's risk register shows that its point-of-sale terminals run an unsupported operating system. The CIO proposes replacing the terminals over 18 months, but the CISO believes the exposure is unacceptable in the interim. The CEO asks the CISO to recommend a course of action that balances business continuity with risk reduction. Which of the following is the MOST appropriate recommendation?
90A mid-sized manufacturing firm has decided to transfer the risk of a ransomware attack on its production network by purchasing a cyber insurance policy. The policy includes a $1 million coverage limit and a $50,000 deductible. Six months later, a ransomware incident causes $400,000 in recovery costs. The insurer approves the claim. What is the organization's financial responsibility for this incident?
91A healthcare insurer is completing its annual enterprise risk assessment. The CISO has compiled a list of 40 information security risks, each scored for likelihood and impact. The CIO asks which risks should be escalated to the board's risk committee for formal acceptance. What is the MOST appropriate criterion for selecting which risks to escalate?
92An information security manager is integrating risk management with the organization's enterprise risk management (ERM) program. The ERM director asks how information security risk should be reported alongside financial and operational risks. Which of the following is the MOST appropriate approach?
93A software development company is assessing the risk of using a third-party cloud provider to host its source code repository. The security manager must determine whether the provider's security controls are sufficient. Which of the following is the MOST effective way to obtain assurance about the provider's security posture?
94An information security manager at a multinational bank is reviewing the risk assessment methodology. The bank operates in multiple jurisdictions with different regulatory requirements. The manager wants to ensure the methodology produces consistent and comparable risk results across all business units. Which of the following is the MOST important characteristic of the risk assessment methodology?
95A hospital's information security manager is assessing a radiology system that stores patient images on a vendor-managed cloud. The vendor reports a 99.9% uptime SLA and annual SOC 2 Type II reports, but the hospital's radiology staff continue to store local copies on unencrypted workstations for convenience. Which of the following is the MOST appropriate risk treatment for the risk introduced by the local copies?
96A healthcare organization's risk register shows a critical patient-records system with an annualized loss expectancy (ALE) of $2,400,000. A proposed control costs $300,000 per year and is estimated to reduce the ALE to $400,000. The CISO must present the strongest financial justification to the executive committee. Which of the following is the MOST appropriate metric to present?
97A global retailer is preparing to adopt a new cloud-based point-of-sale platform. The CISO must ensure the risk assessment approach is repeatable and comparable over time. Which of the following is the MOST important characteristic of the risk assessment methodology to achieve this?
98A global manufacturing company is expanding its operations into a region with unstable political conditions. The CISO has been asked by the board to provide a recommendation on the risk associated with building a new data center in that region. Which of the following should the CISO do FIRST?
99A global retailer operates point-of-sale systems in 12 countries. The risk register shows a single entry titled 'Payment card data breach' with a likelihood of 4 and an impact of 5. A new CISO argues this entry is too coarse to support treatment decisions. Which action BEST improves the usefulness of the risk register for decision-making?
100A global manufacturer is building a risk register for its operational technology (OT) environment. The CISO wants to ensure the register captures risk at the appropriate level and supports prioritization. Which TWO of the following practices BEST support an effective OT risk register? (Choose two.)
101An information security manager is selecting a risk analysis methodology for a new enterprise resource planning (ERP) deployment. The organization has limited historical incident data, the deployment timeline is aggressive, and executives want a defensible ranking of risks within two weeks. Which approach is MOST appropriate?
102A hospital’s CISO is reviewing a critical clinical application that cannot be patched due to vendor certification constraints. The risk of exploitation is assessed as high. The hospital has implemented network segmentation and enhanced monitoring as compensating controls. Which of the following is the MOST appropriate next step to manage this risk?
103An information security manager is reviewing the organization's risk register and notices that a risk related to unpatched software has been assigned a risk score of 9 (on a scale of 1-10) with a note that the risk is 'accepted' because patching would disrupt a critical production system. Which of the following should the manager do NEXT?
104An insurance company's risk committee has formally approved a risk treatment plan that relies on a new identity governance platform to reduce excessive access privileges. Six months into implementation, the project is 20 percent complete due to competing priorities. What should the information security manager do FIRST?
105A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?
106A security analyst is identifying assets to include in a risk assessment for a new e-commerce platform. The platform will process credit card payments and store customer personal information. Which of the following should be considered the MOST critical asset to protect?
107A retail company's risk committee is reviewing the annual risk assessment. The CISO notes that the organization's stated risk appetite for customer data confidentiality is low, but a business unit wants to launch a loyalty program that shares purchase history with a third-party analytics provider. Which of the following should the CISO do FIRST?
108A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?
109A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?
110A healthcare insurer's third-party risk manager learns that a critical claims-processing vendor has been acquired by a foreign parent company subject to different data protection laws. The vendor contract contains no change-of-control clause. What should the risk manager do FIRST?
111A financial services firm is building a risk register for its information security program. The CISO wants to ensure the register supports effective risk treatment decisions. Which TWO of the following elements are MOST essential to include for each identified risk? (Choose two.)
112A manufacturing company is integrating a newly acquired subsidiary into its enterprise risk management program. The CISO must establish controls to ensure risk assessments from the subsidiary are reliable. Which TWO of the following activities BEST provide assurance that the subsidiary's risk assessment results are trustworthy? (Choose two.)
113An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)
114An information security manager is reviewing a risk assessment for a core banking application. The assessment shows a high likelihood of insider misuse of privileged accounts and a high impact on regulatory compliance. The application owner proposes adding database activity monitoring, but the budget is limited and the control would take nine months to deploy. Which of the following is the MOST appropriate immediate action?
115An information security manager is calculating the annualized loss expectancy for a data center outage. The facility has a single point of failure, and a full outage is estimated to occur once every 25 years with a loss of $4,000,000 per event. A redundant power and cooling project would cost $900,000 and reduce the frequency to once every 100 years. What is the expected annual risk reduction, and how should the manager interpret it?
116A CISO is explaining the concept of risk appetite to a newly formed security steering committee. Which of the following BEST describes risk appetite?
117A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?
118A security manager is building a risk register for a newly deployed customer relationship management platform. Which TWO of the following entries are most appropriate to record as risks rather than as controls or assets? (Choose two.)
119An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?
120A security manager is selecting a risk analysis method for a new mobile banking feature. The team has limited historical data, and leadership wants a defensible view of which threats matter most before committing budget. Which approach BEST fits this situation?
121A risk manager is updating the organization's risk assessment methodology. The current approach uses a qualitative scale (High/Medium/Low) for likelihood and impact. Senior management wants a more objective and consistent way to compare risks across different business units. Which of the following should the risk manager implement to BEST meet this requirement?
122An organization's risk appetite statement says it will tolerate only low residual risk for systems processing payment card data. A recent assessment shows a payment gateway with medium residual risk after existing controls. What should the information security manager do NEXT?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
You must quantify risk using SLE, ARO, and ALE, then compare residual risk against the stated appetite to recommend treatment. The single most important thing: risk decisions and acceptance belong to the business owner, while security advises, monitors, and reports.
The Courseiva CISM question bank contains 122 questions in the Information Security Risk Management domain, covering the 20% of the exam attributed to this domain in the official ISACA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Information Security Risk Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included